Skip to content

Detection and Response Engineer

170k – 256kUnited StatesRemote5+ YOE
Summary

Detection and Response Engineer investigates security events, builds threat detections, architects scalable incident response processes with automation, and coordinates multi-team responses. Requires 5+ years in detection engineering, forensics, IR, or threat intelligence, plus Python and cloud experience.

About the role

Responsibilities

  • Investigating security events across the organization using experience in log analysis, digital forensics, or malware analysis.
  • Creating, deploying and maintaining high signal threat detections based on threat actor TTPs.
  • Architecting a highly scalable incident response process by developing, applying and refining automation for Incident Response life cycle steps.
  • Coordinating multi-functional incident response during security incidents, assisting partner teams during non-security incidents.
  • Researching new detection mechanisms for attack vectors and techniques relevant to our space and presenting findings to internal and external audiences.
  • Evaluating external tooling, developing new automation and tooling.
  • Helping to rapidly scale the team, maturing tooling, best practices, engineering processes, and hiring.

Qualifications

  • 5+ years experience in Detection and Response (Detection Engineering, Digital Forensics, Incident Response, and/or Threat Intelligence).
  • Strong communicator with both words and data to a wide variety of stakeholders under varying conditions.
  • Experience as an incident responder leading multi-team incidents.
  • Technical innovation skills, finding technical solutions, learning new technology, evangelizing security and privacy.
  • Ability to move forward major projects in ambiguous situations through influence.
  • Practical experience with attacker tactics, techniques, and procedures (TTPs).
  • Comfortable with complexity short-term but building towards simplicity long-term.
  • Experience with cloud environments and automation.
  • Relevant development experience in at least one scripting language, preferably Python.
Skills
PythonLog AnalysisDigital ForensicsMalware AnalysisIncident ResponseThreat DetectionTTPsCloud EnvironmentsAutomationScripting
Similar roles at this salary range
All Security Engineering jobs →
Shield AI

Senior Staff Cybersecurity Engineer, Platform Security

Senior technical owner building secure-by-default infrastructure, IaC modules, policy-as-code guardrails, and CI/CD security tooling for cloud and platform engineering teams.

160k – 240kSan Diego, CASecurity EngineeringOn-site7+ YOEGoOPA
Upstart

Principal Security Engineer, Data Security

Principal-level security engineer defining infrastructure security strategy and leading cross-functional efforts to secure cloud, Kubernetes, and developer platforms at scale.

191k – 264kUnited StatesSecurity EngineeringRemote8+ YOEGoAWS
Brex

Senior Application Security Engineer

Senior Application Security Engineer focused on finding vulnerabilities, performing penetration testing, and building security tooling across Brex's platform. Requires 5+ years in application security with strong Python and AI workflow knowledge.

192k – 240kUnited StatesSecurity EngineeringRemote5+ YOEAWSgRPC
Apollo

Senior Application Security Engineer

Senior individual contributor responsible for strengthening Apollo's secure software development lifecycle, performing application security reviews, threat modeling, vulnerability management, and AI security for product, platform, and AI-powered features.

190k – 273kUnited StatesSecurity EngineeringRemote5+ YOEGCPRuby
Metropolis

Senior Security Engineer, Infrastructure & Network Security

Lead AWS and network security infrastructure, zero-trust initiatives, and cloud automation for enterprise environments. Requires strong AWS, networking, IAM, and scripting experience.

160k – 215kLos Angeles, CASecurity EngineeringOn-site5+ YOEAWSVPN